PT-2018-11032 · Dell Emc+1 · Openmanage Essentials+2
Publicado
2018-02-12
·
Atualizado
2018-03-12
·
CVE-2018-1214
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC SupportAssist Enterprise versions 1.1 through 1.2
Description
The issue arises from the creation of a local Windows user account named
OMEAdapterUser with a default password during the installation of Dell EMC SupportAssist Enterprise. This account remains after upgrading from version 1.1 to 1.2. Knowledge of the default password can allow unauthorized access to the management console. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser account is added to the OmeAdministrators group, potentially allowing an unauthorized person with the default password to gain access to the affected OME installation with OmeAdministrators privileges.Recommendations
For versions 1.1 through 1.2, update to version 1.2.1 to resolve the issue.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Emc Supportassist Enterprise
Openmanage Essentials
Windows